IP Library › Granted Patent US 12,229,258
Granted Patent B2
US 12,229,258 · App. 17/970,580 · Granted Feb 18, 2025

System, method, and apparatus for smart whitelisting/blacklisting

Inventors: Robert J. Cheng (Myrtle Beach, SC); Robert J. Woodworth, Jr. (Charleston, SC); Andrew Tuch (Boca Raton, FL); Matthew Quincy Riley (Owosso, MI); Devin R. Bergin (Myrtle Beach, SC)
Assignee: PC MATIC, INC.
G06F21/56G06F21/51G06F2221/033G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,258
App. No.
17/970,580
Granted
Feb 18, 2025
Kind
B2
Abstract

A system for intelligent managing whitelists and blacklist provides options and/or suggestions to the administrators and/or information technology team to allow administration of whitelists and/or blacklists based upon history and rules. For example, if permission to run a certain program is requested by several people in a group or organization and the program is not believed to have a virus, then, the administrator if presented with an option to enable (e.g., add to the whitelist) that program for the entire group or organization.

Claims (39)

1. A system for computer security, the system comprising:

a server computer;

an administrative program running on the server computer;

means for requesting a target activity be enabled on a device;

when a request for the target activity is received:

information regarding the request is added to a history file by the administrative program;

the administrative program runs a set of rules for the request using the history file to make a recommendation;

when the recommendation indicates that the target activity be enabled on a single device, a whitelist and/or a blacklist is modified to enable the target activity at the device and the whitelist and/or the blacklist is distributed by the administrative program to the device;

when a positive response is received by the administrative program responsive to the recommendation, the whitelist and/or the blacklist is modified to enable the target activity and the whitelist and/or the blacklist is distributed by the administrative program to a plurality of devices based upon the recommendation; and

when a negative response is received by the administrative program responsive to the recommendation, the whitelist and/or the blacklist is modified to enable the target activity and the whitelist and/or the blacklist is distributed by the administrative program to the device.

2. The system of claim 1 , wherein the target activity to run a program.

3. The system of claim 1 , wherein the target activity to run a script.

4. The system of claim 1 , wherein the target activity to access a unified resource link.

5. The system of claim 1 , wherein the means for requesting the target activity be enabled comprises a transaction sent from the device to the server computer after an attempt to perform the target activity on the device.

6. The system of claim 1 , wherein the means for requesting the target activity be enabled comprises an email sent from a user of the device to an admirative person having access to the server computer.

7. The system of claim 1 , wherein the means for requesting the target activity be enabled comprises a phone call from a user of the device to an admirative person having access to the server computer.

8. The system of claim 1 , wherein the recommendation includes an identification of an organization for which the target activity is to be enabled.

9. A method for computer security, the method comprising:

requesting, by a user of a device, that a target activity be enabled on the device and responsive to the requesting by the user:

adding information regarding the target activity to a history file;

making a recommendation using a set of rules and the history file;

when the recommendation indicates that the target activity be enabled on a single device, modifying a whitelist and/or a blacklist to enable the target activity at the device and distributing the whitelist and/or the blacklist to the device;

when receiving a positive response to the recommendation, modifying the whitelist and/or the blacklist to enable the target activity and distributing the whitelist and/or the blacklist to a plurality of devices based upon the recommendation; and

when receiving a negative response to the recommendation, modifying the whitelist and/or the blacklist to enable the target activity and distributing the whitelist and/or the blacklist to the device.

10. The method of claim 9 , wherein the target activity to run a program.

11. The method of claim 9 , wherein the target activity to run a script.

12. The method of claim 9 , wherein the target activity to access a unified resource link.

13. The method of claim 9 , wherein the step of requesting by the user of the device that the target activity be enabled on the device comprises the device sending a transaction to a server computer after the user attempting to perform the target activity on the device.

14. The method of claim 9 , wherein the step of requesting by the user of the device that the target activity be enabled on the device comprises sending an email from the user of the device to an admirative person.

15. The method of claim 9 , wherein the step of requesting by the user of the device that the target activity be enabled on the device comprises making a phone call by the user of the device to an admirative person.

16. The method of claim 9 , wherein the recommendation includes an identification of an organization for which the target activity is to be enabled.

17. A method of protecting a device, the method comprising:

upon a program attempting to be run on the device, protection software running on the device determining whether the program is allowed to run based upon a blacklist and a whitelist, the program is allowed to run based upon the program being absent from the blacklist or the program is allowed to run based upon the program being absent from the blacklist and present on the whitelist, thereby allowing the program to run on the device;

otherwise, when the program is present on the blacklist and absent from the whitelist, the protection software preventing the program from running on the device and the protection software sending a transaction to administrative software running on a server, the transaction comprising details of the program;

responsive to receiving the transaction at the server, the administrative software running on the server saving the details of the program in a history file and, the administrative software running on the server analyzing the history file with respect to a set of rules to determine a recommendation for enabling the program, when the recommendation indicates to enable the program on a single device, the administrative software running on the server modifying the whitelist and/or the blacklist to enable the program at the device and the administrative software running on the server distributing the whitelist and/or the blacklist to the device; and

otherwise, when the recommendation indicates to enable the program on a plurality of devices within an organization, the administrative software running on the server modifying the whitelist and/or the blacklist to enable the program and the administrative software running on the server distributing the whitelist and/or the blacklist to the plurality of devices.

18. The method of claim 17 , wherein the recommendation includes an identification of the organization for which the program is to be enabled.

19. The method of claim 17 , wherein after the administrative software running on the server analyzing the history file with respect to the set of rules to determine the recommendation for enabling the program, presenting the recommendation for approval by an administrative person.

20. The method of claim 17 , wherein the recommendation includes all devices associated with the organization of a company or all devices associated with an entire company.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2022
From: RILEY, MATTHEW QUINCY; CHENG, ROBERT J.; WOODWORTH, ROBERT J., JR; TUCH, ANDREW; BERGIN, DEVIN R.
To: PC MATIC INC.
Reel/Frame 061490/0689 →
Continuity (5)
Continuation In Part 17689367 · Mar 8, 2022
Continuation In Part 17246869 · May 3, 2021
Continuation In Part 17134716 · Dec 28, 2020
Continuation In Part 17018427 · Sep 11, 2020
Related Publication 20230038774A1 · Feb 9, 2023
References Cited (34)
US 9117075B1 · Yeh · 2015 [cited by examiner]
US 10853058B1 · Ouzan · 2020 [cited by examiner]
US 11416561B1 · Satish · 2022 [cited by examiner]
US 20030172167A1 · Judge · 2003 [cited by examiner]
US 20110047597A1 · Mahaffey · 2011 [cited by examiner]
US 20110145920A1 · Mahaffey · 2011 [cited by examiner]
US 20120030731A1 · Bhargava · 2012 [cited by examiner]
US 20130097659A1 · Das · 2013 [cited by examiner]
US 20140032691A1 · Barton · 2014 [cited by examiner]
US 20140040979A1 · Barton · 2014 [cited by examiner]
US 20140165130A1 · Zaitsev · 2014 [cited by examiner]
US 20140245376A1 · Hibbert · 2014 [cited by examiner]
US 20150339475A1 · Feroz · 2015 [cited by examiner]
US 20160321452A1 · Richardson · 2016 [cited by examiner]
US 20160359913A1 · Gupta · 2016 [cited by examiner]
US 20160373486A1 · Kraemer · 2016 [cited by examiner]
US 20180307840A1 · David · 2018 [cited by examiner]
US 20190089678A1 · Lam · 2019 [cited by examiner]
US 20190108342A1 · Conikee · 2019 [cited by examiner]
US 20190325135A1 · David · 2019 [cited by examiner]
US 20200167473A1 · Polyakov · 2020 [cited by examiner]
US 20200285752A1 · Wyatt · 2020 [cited by examiner]
US 20200285761A1 · Buck · 2020 [cited by examiner]
US 20200302058A1 · Kenyon · 2020 [cited by examiner]
US 20200382470A1 · Butler · 2020 [cited by examiner]
US 20200394295A1 · Ikram · 2020 [cited by examiner]
US 20230038774A1 · Cheng · 2023 [cited by examiner]
Turaev, Hasan et al. Prevention of Ransomware Execution in Enterprise Environment on Windows OS: Assessment of Application Whitelisting Solutions. 2018 1st International Conference on Data Intelligence and Security (ICD… [cited by examiner]
Powers, Josh et al. Whitelist malware defense for embedded control system devices. 2015 Saudi Arabia Smart Grid (SASG). https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7449271 (Year: 2015). [cited by examiner]
He, Daojing et al. Mobile application security: malware threats and defenses. IEEE Wireless Communications, vol. 22, Issue: 1. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7054729 (Year: 2015). [cited by examiner]
Wibowo, Fahrudin Mukti et al. Collaborative Whitelist Packet Filtering Driven by Smart Contract Forum. 2019 International Seminar on Research of Information Technology and Intelligent Systems (ISRITI). https://ieeexplor… [cited by applicant]
Rezvani, Mohsen et al. Anomaly-free policy composition in software-defined networks. 2016 IFIP Networking Conference (IFIP Networking) and Workshops. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&amnumber=7 497226 (Ye… [cited by applicant]
Turaev, Hasan et al. Prevention of Ransomware Execution in Enterprise Environment on Windows OS: Assessment of Application Whitelisting Solutions. 2018 1st International Conference on Data Intelligence and Security (ICD… [cited by applicant]
Powers, Josh et al. Whitelist malware defense for embedded control system devices. 2015 Saudi Arabia Smart Grid (SASG). https://ieeexplore.ieee.org/starnp/starp.jsp?tp=&arnurnber=7 449271 (Year: 2015). [cited by applicant]